Re: Redundant Data Center Architectures

2009-10-28 Thread Roland Dobbins
cisco.com/en/US/products/hw/contnetw/ps4162/> ----------- Roland Dobbins // <http://www.arbornetworks.com> Sorry, sometimes I mistake your existential crises for technical insights. -- xkcd #625

Re: ip options

2009-10-28 Thread Roland Dobbins
forms also have the option to ignore, rather than drop. --- Roland Dobbins // <http://www.arbornetworks.com> Sorry, sometimes I mistake your existential crises for technical insights. -- xkcd #625

Re: Pros and Cons of Cloud Computing in dealing with DDoS

2009-11-05 Thread Roland Dobbins
e domains for botnet C&C. IaaS abused to launch DDoS won't be far behind. --- Roland Dobbins // <http://www.arbornetworks.com> Sorry, sometimes I mistake your existential crises for technical insights. -- xkcd #625

Re: Pros and Cons of Cloud Computing in dealing with DDoS

2009-11-05 Thread Roland Dobbins
cs, of course). I'm also saying that threats to availability aren't something one can always assume one will be able to handle alone; engaging with the larger opsec community is key. ----------- Roland Dobbins // <http

Re: NTP Md5 or AutoKey?

2008-11-03 Thread Roland Dobbins
highly dependent upon an accurate time-hack, as well. --- Roland Dobbins <[EMAIL PROTECTED]> // +852.9133.2844 mobile History is a great teacher, but it also lies with impunity. -- John Robb

Re: UDP DoS mitigation?

2008-12-12 Thread Roland Dobbins
hardware-based edge platform, be sure to first investigate all the particulars of its uRPF implementation so as to ensure that you can use it for S/RTBH, and if at all possible, test it before buying. --- Roland Dobbins

Re: UDP DoS mitigation?

2008-12-12 Thread Roland Dobbins
ware-based platform is required to deal with high pps rates (the Cisco equivalent is the ASR1000; I'm not familiar with boxes from other vendors, but I'm pretty sure there are others in this same class). ------

Re: Failover solution using BGP

2008-12-31 Thread Roland Dobbins
ss complex, et. al. ------- Roland Dobbins // +852.9133.2844 mobile All behavior is economic in motivation and/or consequence.

Re: Failover solution using BGP

2008-12-31 Thread Roland Dobbins
the back-end is monolithic - and it's more nearly a complete solution, with more options, granularity, and safeguards available, than one based upon routing alone. ------- Roland Dobbins // +852.9133.2844 mobile All beh

Re: Ethical DDoS drone network

2009-01-04 Thread Roland Dobbins
urces, even though it isn't nearly as entertaining. ------- Roland Dobbins // +852.9133.2844 mobile All behavior is economic in motivation and/or consequence.

Re: Ethical DDoS drone network

2009-01-04 Thread Roland Dobbins
e: Entertainment has (should have?) nothing to do with it. Implementing BCPs is drudgery; because of this, it often receives short shrift. ----------- Roland Dobbins // +852.9133.2844 mobile All behavior is economic in motivation and/or consequence.

Re: Ethical DDoS drone network

2009-01-05 Thread Roland Dobbins
oss this happy circumstance in any organization who've asked me about this kind testing, FWIW. --- Roland Dobbins // +852.9133.2844 mobile All behavior is economic in motivation and/or consequence.

Re: Ethical DDoS drone network

2009-01-05 Thread Roland Dobbins
a lab setup which reflects production for many reasons having nothing to do with security). --- Roland Dobbins // +852.9133.2844 mobile All behavior is economic in motivation and/or consequence.

Re: Ethical DDoS drone network

2009-01-05 Thread Roland Dobbins
eezing the design and initiating deployment. ------- Roland Dobbins // +852.9133.2844 mobile All behavior is economic in motivation and/or consequence.

Re: Ethical DDoS drone network

2009-01-05 Thread Roland Dobbins
This seems to be a relatively rare attitude, unfortunately. ------- Roland Dobbins // +852.9133.2844 mobile All behavior is economic in motivation and/or consequence.

Re: Ethical DDoS drone network

2009-01-06 Thread Roland Dobbins
commercial tools, which've been available for many years. And again, it comes back to understanding the performance envelope of one's equipment, even without simulation. ------- Roland Dobbins // +852.9133.2844 mobil

Re: Ethical DDoS drone network

2009-01-06 Thread Roland Dobbins
7;t been implemented, it makes little sense to expend scarce resources testing when those resources could be better-employed hardening and increasing the resiliency and robustness of said network/system. ------- Rola

Re: Are we really this helpless? (Re: isprime DOS in progress)

2009-01-23 Thread Roland Dobbins
)? Did you have to pay a termination fee to get out of the arrangement? --- Roland Dobbins // +852.9133.2844 mobile All behavior is economic in motivation and/or consequence.

Re: Great outage of 1997 - Does anyone recall?

2009-02-21 Thread Roland Dobbins
On Feb 22, 2009, at 2:28 PM, neal rauhauser wrote: Does anyone have the full story on this? <http://www.merit.edu/mail.archives/nanog/1997-04/msg00444.html> --- Roland Dobbins // +852.9133.2844 mobile Some thin

Re: Great outage of 1997 - Does anyone recall?

2009-02-21 Thread Roland Dobbins
is: <http://www.unixwiz.net/techtips/iguide-kaminsky-dns-vuln.html> ------- Roland Dobbins // +852.9133.2844 mobile Some things are just too precious to entrust to computers. -- Seth Hanford

Re: DPI or Flow Management

2009-03-01 Thread Roland Dobbins
tacks. --- Roland Dobbins // +852.9133.2844 mobile Some things are just too precious to entrust to computers. -- Seth Hanford

Re: DPI or Flow Management

2009-03-01 Thread Roland Dobbins
On Mar 2, 2009, at 9:10 AM, Roland Dobbins wrote: With regards to DDoS mitigation, it's sometimes necessary to go above layers-3/-4 in the event of layer-7-targeted attacks. In fact, it's sometimes important to have the ability to parse packet payloads and/or interact with traff

Re: ACLs vs. full firewalls

2009-04-07 Thread Roland Dobbins
th the chosen policy-enforcement regime. ------- Roland Dobbins // +852.9133.2844 mobile Our dreams are still big; it's just the future that got small. -- Jason Scott

Re: Do we still need Gi Firewall for 3G/UMTS/HSPA network ?

2009-04-09 Thread Roland Dobbins
d concerns. ------- Roland Dobbins // +852.9133.2844 mobile Our dreams are still big; it's just the future that got small. -- Jason Scott

Re: Do we still need Gi Firewall for 3G/UMTS/HSPA network ?

2009-04-09 Thread Roland Dobbins
should be deployed to protect the GGSN, et. al. ------- Roland Dobbins // +852.9133.2844 mobile Our dreams are still big; it's just the future that got small. -- Jason Scott

Re: Do we still need Gi Firewall for 3G/UMTS/HSPA network ?

2009-04-09 Thread Roland Dobbins
cture, stateless ACLs in hardware will work quite well. --- Roland Dobbins // +852.9133.2844 mobile Our dreams are still big; it's just the future that got small. -- Jason Scott

Re: SIP - perhaps botnet? anyone else seeing this?

2009-04-10 Thread Roland Dobbins
or so. --- Roland Dobbins // +852.9133.2844 mobile Our dreams are still big; it's just the future that got small. -- Jason Scott

Re: SIP - perhaps botnet? anyone else seeing this?

2009-04-10 Thread Roland Dobbins
d* specific complaints, did you not? ;> ----------- Roland Dobbins // +852.9133.2844 mobile Our dreams are still big; it's just the future that got small. -- Jason Scott

Re: IXP

2009-04-18 Thread Roland Dobbins
ll as implementing layer-3 anti- spoofing on a per-switchport basis (i.e., BCP38 on a per-switchport basis)? --- Roland Dobbins // +852.9133.2844 mobile Our dreams are still big; it's just the future that

Re: monitoring tools

2007-10-30 Thread Roland Dobbins
would recommend taking a look at NetFlow and starting with an open-source tool like nfsen/nfdump. --- Roland Dobbins <[EMAIL PROTECTED]> // 408.527.6376 voice I don't sound like nobody.

[NANOG] OT: Planetary-Scale Views on a Large Instant-Messaging Network.

2008-04-26 Thread Roland Dobbins
Interesting Microsoft Research piece on macro-scale user behaviors: <http://research.microsoft.com/~horvitz/leskovec_horvitz_www2008.pdf> --- Roland Dobbins <[EMAIL PROTECTED]> // +66.83.266.6344 mobile

Re: [NANOG] OSPF minutia, and, technote publication venues

2008-05-05 Thread Roland Dobbins
eting (after acceptance by the Program Committee, which acts as a gate), and then the NANOG folks post the documents along with any slides and the VoDs of their presentations, in the usual fashion? ----------- Roland

Re: [NANOG] OSPF minutia, and, technote publication venues

2008-05-05 Thread Roland Dobbins
ional information which folks have both the time and inclination to write up, but which they don't due to the perceived lack of an appropriate review/publication mechanism utilized by their intended audience? -----------

Re: DNS problems to RoadRunner - tcp vs udp

2008-06-15 Thread Roland Dobbins
d out. --- Roland Dobbins <[EMAIL PROTECTED]> // +66.83.266.6344 mobile History is a great teacher, but it also lies with impunity. -- John Robb

Re: EC2 and GAE means end of ip address reputation industry? (Re: Intrustion attempts from Amazon EC2 IPs)

2008-06-22 Thread Roland Dobbins
amount large-scale enterprise computing (like banking, pharma, government, and so forth) will take place. I foresee interesting times ahead. ------- Roland Dobbins <[EMAIL PROTECTED]> // +66.83.266.6344 mobile His

Re: Hardware capture platforms

2008-07-30 Thread Roland Dobbins
can also export NetFlow telemetry based upon the captured traffic. Arbor, Narus, and Lancope have similar NetFlow-via-packet-capture capabilities. --- Roland Dobbins <[EMAIL PROTECTED]> // +66.83.266.6344 mobile H

Re: load balancer product for dns content switching

2015-08-27 Thread Roland Dobbins via NANOG
On 28 Aug 2015, at 6:29, William Cooper wrote: > A10, brocade, etc dnsdist, as well. --- Roland Dobbins

<    1   2   3   4   5